Access violation vulnerability in HUSKY – Products Filter Professional for WooCommerce 1.3.6.1

A plugin called “HUSKY – Products Filter Professional for WooCommerce” on WordPress has a security issue in all versions up to 1.3.6.1. This is because it does not properly check for a user’s permission when using a certain action called “woof_messenger_remove_subscr”. This means that someone who is logged in and has at least subscriber access can unsubscribe other users from receiving product notifications. They just need to figure out or guess the right key for the user they want to unsubscribe. This only affects users who have the Products Messenger extension enabled.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.